---
cve: "CVE-2018-20843"
severity: "HIGH"
cvss: 7.5
epss: "7.1%"
vendor: "n/a"
kev: false
exploited: false
published: "2019-06-24 17:15:09"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T12:08:28+02:00"
---

# CVE-2018-20843

> 7.5 HIGH · 🧪 PoC

## Beschreibung

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- d3b78b42a2dcdea98e22625cfff67a49d47e6025 (Commit)

## Referenzen

- <https://usn.ubuntu.com/4040-1/>
- <https://usn.ubuntu.com/4040-2/>
- <https://www.debian.org/security/2019/dsa-4472>
- <https://seclists.org/bugtraq/2019/Jun/39>
- <https://lists.debian.org/debian-lts-announce/2019/06/msg00028.html>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CEJJSQSG3KSUQY4FPVHZ7ZTT7FORMFVD/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IDAUGEB3TUP6NEKJDBUBZX7N5OAUOOOK/>
- <http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00039.html>
- <https://security.gentoo.org/glsa/201911-08>
- <https://www.oracle.com/security-alerts/cpuapr2020.html>
- <https://www.oracle.com/security-alerts/cpuoct2020.html>
- <https://github.com/libexpat/libexpat/issues/186>
- <https://github.com/libexpat/libexpat/pull/262>
- <https://github.com/libexpat/libexpat/pull/262/commits/11f8838bf99ea0a6f0b76f9760c43704d00c4ff6>
- <https://github.com/libexpat/libexpat/blob/R_2_2_7/expat/Changes>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-20843) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
